Latest stories — Page 26

UC Riverside Tool Traces Deepfake Videos Back to the AI That Made Them
Researchers have built software that can identify not just whether a video is AI-generated, but which specific model created it, a step that could help hold AI companies accountable for harmful content.

CISA flags N-able N-central bug as actively exploited, orders federal fix
The remote monitoring platform used by thousands of IT providers carries an authentication bypass that attackers are already using in the wild.

DOUBLECUP: the new Russian malware service that hides code inside cached images
A service called DOUBLECUP tricks users into pasting rogue commands, then pulls malware out of PNG files sitting in the browser's cache.

Fake Roblox Cheat Tool Hides Password Stealer and Remote Spy Software
Bitdefender says a months-long campaign is pushing booby-trapped copies of the Xeno script runner to Roblox players, planting malware that steals browser logins, drains crypto wallets and hands attackers full control of the PC.

Fake npm Packages Pose as Alibaba Developer Tools, Drop Remote-Control Malware
Researchers found 18 booby-trapped packages on the npm registry aimed at Chinese-speaking developers, using a classic name-squatting trick to smuggle in a cross-platform remote access trojan.

Cyberattack Strikes Liechtenstein's Register of Company and Foundation Owners
Criminals hit a government database designed to fight money laundering, raising fresh questions about how well sensitive ownership records are protected.

Malware Can Silently Hijack Chrome Passkeys, Researchers Show
Palo Alto's Unit 42 details three attack paths against Google Password Manager that let ordinary user-level malware sign in without a fingerprint, PIN, or on-screen prompt.

Black Hat 2026: Every Major Security Product Launch You Need to Know
Fifteen vendors dropped new tools at Las Vegas this week. Here is what they actually do, why it matters, and what the pattern of announcements tells us about where the industry thinks the next wave of attacks is coming from.

Visa Is Buying Fraud-Detection Firm BioCatch for $2.4 Billion
The payments giant wants BioCatch's technology, which watches how you move through a banking app, to help banks catch scammers before money leaves an account.

UK Police Legal Database Breach Exposes 100,000+ Officers as ICO and NCA Step In
The Police National Legal Database has confirmed contact details of officers and criminal justice staff were stolen, with the ExfilSquad group claiming 135,000 records and demanding a ransom.

BTMOB Android spyware splinters into a messy resale market
What started as a single Android remote-access tool for hire has fractured into resellers, source-code buyers and impersonators trading under the same name.

A Week of Doors Left Open: Rogue AI, an $88M Bitcoin Heist, and Water Systems Under Attack
From a chatbot that wandered past its guardrails to a cryptocurrency wallet undone by weak randomness, this week's incidents share one thread: access nobody meant to give.

98% of Cybersecurity Leaders Report Job Stress. The Fix Isn't More Hiring.
A major industry survey finds that stress among security chiefs has become the norm, not the exception. The real problem, argues one senior researcher, is a design flaw in how organisations treat the role itself.

Why Locking Down What AI Agents Can Do Is Not Enough
A security firm says the real question is not what you told your AI to do. It is how far it can wander if something goes wrong.

River Bank Paid Hackers to Delete Stolen Data After June Ransomware Attack
Alabama's River Bank & Trust was hit by ransomware in June. The bank appears to have paid the criminals to destroy what they took, but still cannot confirm whether customer data was exposed.

Horizon3.ai Raises $250 Million as Demand for Automated Security Testing Grows
The cybersecurity firm behind autonomous penetration testing just landed a major funding round. Here is what the company does, why investors are paying attention, and what it means for the broader security market.

Where AI Tools Like Claude Actually Belong in the Security Team
Security leaders are under pressure to adopt AI fast. Here is a plain-English look at what platforms like Claude, Codex and Cursor really do inside a security operations centre, and the policy questions that come with them.

Fake Amazon Login Pages Hide a Chinese iPhone Hacking Campaign
Researchers say a Chinese group is running more than 100 lookalike sign-in sites to attack iPhones with a leaked hacking kit called DarkSword.

UK Police Legal Database Leaked to Dark Web After July Breach
Names, work emails and organisational details of officers, criminal justice staff and government partners were posted online after intruders hit the Police National Legal Database.

INC Ransomware Gang Is Exploiting Two Critical SonicWall Flaws, And Calling Victims Afterward
A ransomware group has weaponised two newly discovered holes in widely used remote-access devices, hitting targets across five countries. The criminals are now also cold-calling victims to pile on the pressure.

Your Company's Vendor Problem Starts Before Anyone Calls Security
When businesses pick software first and ask security questions second, they hand criminals a head start. Here is why fixing that order matters, and what a grown-up process actually looks like.